The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product. Learn more about how Cisco is using Inclusive Language.
This document describes the features, issues, and exceptions of Cisco NX-OS Release 9.3(8) software for use on Cisco Nexus 9000 Series switches.
Note: The documentation set for this product strives to use bias-free language. For the purposes of this documentation set, bias-free is defined as language that does not imply discrimination based on age, disability, gender, racial identity, ethnic identity, sexual orientation, socioeconomic status, and intersectionality. Exceptions may be present in the documentation due to language that is hardcoded in the user interfaces of the product software, language used based on RFP documentation, or language that is used by a referenced third-party product.
The following table lists the changes to this document.
Table 1. Changes to this Document
Date |
Description |
August 6, 2021 |
Cisco NX-OS Release 9.3(8) became available. |
October 5, 2021 |
Added details about ‘Thousand Eyes (TE) Integration’ feature in the ‘New and Enhanced Software Features’ section. |
April 25, 2024 |
Added CSCwh50989 and CSCwe53655 to Open Issues. |
New and Enhanced Software Features
New Features |
|
Feature |
Description |
Thousand Eyes (TE) Integration |
Introduced Thousand eyes integration support with Cisco Nexus 9000 Series switches. For product overview look at:
It is a must to install the following general SMU when TE integration is performed:
nxos.CSCvz52812-n9k_ALL-1.0.0-9.3.8.lib32_n9000.tar
For SMU installation please refer to the following guide:
|
The enhanced feature listed below are existing features introduced in earlier releases but enhanced with new support in Cisco NX-OS Release 9.3(8).
Enhanced Features |
|
Feature |
Description |
SNMP Salt Hash |
With this enhancement the hashed passwords are integrated with salt to generate the final digest password to avoid security concerns for SNMPv3 users. For more information, see the Cisco Nexus 9000 Series NX-OS System Management Configuration Guide, Release 9.3(x) . |
There are no new hardware features introduced in Cisco NX-OS Release 9.3(8).
Bug ID |
Description |
Headline: Crash in Nexus 9000 Fatal Module Error when downgrading - service port_client hap reset
Symptoms: During downgrade from 9.3.7 to 9.3.6, vPC peer switch reloads due to "port_client" service crash: Service: port_client Description: Port Client Daemon Executable: /lc/isan/bin/port_client
Workarounds: No workaround. The switch is reloaded when the issue is hit. |
|
Headline: 9500-R :: Feature ptp causes the spine switch to intercept unicast ARP replies in VxLAN fabric
Symptoms: The L2 adjacent host are not able to resolve each other’s ARP across VxLAN fabric. The broadcasted ARP reply is flooded correctly and reaches all hosts, however the unicast ARP reply is lost inside of the fabric. In fact the ARP replies are redirected to SPINE CPU instead of being forwarded. Other unicast communication works fine (for example - when we configure static ARPs).
Workarounds: · Disable 'feature nv overlay' on spine. This will avoid this problem and also will ensure better hashing of packets over ECMP links. · Enable "arp suppression" or · Remove "feature ptp" from the spines. After doing so, "reload" or "reload ascii" is required to restore connectivity. |
|
Headline: Vxlan unicast traffic drop due to mac learnt on FEXAA HIFVPC getting deleted on vpc primary.
Symptoms: Mac address behind FEX AA VPC is getting deleted on primary vpc peer after reload of switch (primary reloaded followed by secondary). On secondary the MAC entry is present. This is causing VXLAN unicast traffic to get dropped.
Workarounds: · Flap the HIFVPC interface. · Delete the particular mac address and allow mac to be learnt again. |
|
Headline: NXOS - Additional prompt showing up when running guest-shell command.
Symptoms: Running guestshell prompts for password which is unexpected after upgrading from switch with guestshell version 2.10 to NXOS version 9.3(8) or 10.1(2).
Workarounds: Remove and re-enable guestshell after the upgrade. |
|
Headline: Revert reserved MAC blocking behavior for VRRP macs on SVIs
Symptoms: User is not able to configure VRRP VMAC on SVI interfaces.
Workarounds: None. |
|
Headline: Custom COPP causing transit traffic to be punted to the CPU on Nexus 9300-GX2
Symptoms: When custom-COPP policy contains ACL rules which match on Layer 4 destination or source port, transit traffic also hits the COPP and the packets are copied to CPU. This causes duplication of traffic as CPU also routes the copied packets to the destination.
Workarounds: Custom COPP policy using src/dst match mitigates punt for transit traffic. |
Bug ID |
Description |
Headline: 100M link is down on N9K-C93180YC-FX side and up on peer side after port flap on post ND ISSU.
Symptoms: Link may not come up after ISSU if you have a 100mb FX xcvr.
Workarounds: You need to have physical OIR of 100mb FX xcvr to recover or you need to reload the switch. |
|
Headline: Nexus 9000 aclqos cores - ERSPAN w/source VLAN mapped to VNI on certain ports
Symptoms: Gen1 Nexus 9000 models may see a core file from the aclqos process when trying to do an ERSPAN on a VLAN mapped to a VNI, using ports from specific ASICs.
Workarounds: None |
|
Headline: Bringing up SPAN session silently fails when sFlow data sources are configured.
Symptoms: A Nexus 9000 series switch configured with sFlow data sources is not able to administratively bring SPAN sessions online. This is the expected behaviour. However, no error message or feedback to the user is presented if one attempts to bring a SPAN session up while an sFlow data source is configured.
Workarounds: There is no known workaround for this issue. This defect introduces an error message to the CLI of the switch when one attempts to bring a SPAN session up while sFlow data sources are configured on the switch. |
|
Headline: SSH connection rejected with FIPS enabled using any SSH key.
Symptoms: SSH connections will be rejected if the FIPS feature is enabled on release 9.3(7).
Workarounds: Downgrade to release 9.3(6) or earlier, or upgrade to release 10.1(1) or later.
There is a general available SMU to address this issue on release 9.3(7): https://software.cisco.com/download/home/286314783/type/286278856/release/9.3(7)
SMU installation instructions: |
|
Headline: L2FM process crash after l2fm_mcec_get_mac_handler
Symptoms: The L2FM process crashes after the vPC comes online.
Workarounds: Disconnect the vPC peer link and upgrade both peers separately. After they are upgraded and the vPC is connected back, they should remain stable. |
|
Headline: Installing multiple SMUs do not remain committed after reload
Symptoms: When installing multiple SMUs which includes nxos.CSCvx18710-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000.tar (tar includes nxos.CSCvx18710_lc_x86-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000.rpm and nxos.CSCvx18710_lc_x86-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000.rpm), they do not remain committed after reload.
Workarounds: Please use SMU 1.0.1 version for CSCvx18710.
|
|
Headline: L2rib Process Crashes with a Hap Reset due to a Segmentation Fault
|
|
Headline: n9k/ipv6: low memory in MTS due to high ICMPV6 control messages after large host move
Symptoms: High MTS usage in below queues, slow response and possible crash on various processes due to no memory in MTS. High MTS queues: icmpv6/ICMPV6-CTRL netstack/IP MTS queue
Workarounds: NA |
|
Headline: Configuring "vpc role preempt" will cause vPCs with port-type network to go into BKN state.
Symptoms: Nexus switch will show vPC port-channels that are configured for spanning-tree port-type network in BKN state after configuring "vpc role preempt".
Workarounds: Shut, no shut of the affected links on new vpc secondary should recover it. |
|
Headline: MPLS LDP IGP SYNC is not working properly with ISIS.
Symptoms: switch# show mpls ldp igp sync Ethernet1/1: LDP configured; LDP-IGP Synchronization enabled. Sync status: sync achieved; peer reachable. Sync delay time: 0 seconds (0 seconds left) IGP holddown time: infinite. Peer LDP Ident: 20.20.4.4:0 (GR) IGP enabled: isis-4766 Ethernet1/11: LDP not configured; LDP-IGP Synchronization enabled. Sync status: sync not achieved; peer reachable. Sync delay time: 0 seconds (0 seconds left) IGP holddown time: infinite. GR-only Reachability: 20.20.1.1:0 IGP enabled: isis-4766
Workarounds: NA |
|
Headline: ISIS does not propagate topology information to MPLS-TE depending on TLV order.
Symptoms: Some routers are not seen in MPLS-TE topology while ISIS is used as IGP.
Workarounds: NA |
|
Headline: Topology information is not propagated from ISIS to MPLS TE when authentication configured for ISIS
Symptoms: MPLS TE topology (`show mpls traffic-eng topology`) contains no information on other expected nodes, and on those present in ISIS topology.
Workarounds: Configure ISIS authentication on per-interface level and remove it from "router isis" section. |
|
Headline: PIM crashes after configuring - ip pim rp-candidate
Symptoms: The switch reloaded due to the following reason: Service: pim hap reset And there is a PIM core file in the output of - show core.
Workarounds: None |
|
Headline: DEVICE_TEST-2-AUTHENTICATION_FAIL: Module 27 ACT2-Instance-2
Symptoms: A Nexus 9500 switch may report the following in the log:
Workarounds: None |
|
Headline: platform service may crash
|
|
Headline: Nexus 3K/9K - VRRP with object tracking leading to Primary-Primary
1:a) when track does down it decrements the priority as expected b) When track comes up the priority is not returning to the default value 2:a) when track does down on VRRP MASTER so as to trigger a state change to BACKUP as priority is decremented, priority is decremented twice for vrrp group. b) When track comes up the priority is not returning to the default value
|
|
Headline: dhcp_snoop process may crash
|
|
Headline: msdp owned (s,g) mroute does not inherit pim oif from (*,g)
interface Ethernet x/y ip igmp static-oif multicast_group source multicast_sender_ip |
|
Headline: NX-OS can't resolve IPv6 static recursive route with next-hop over EVPN
|
|
Headline: VRF stuck in delete pending because BGP is not dropping the MTS_OPC_L3VM
|
|
Headline: NVE:Snmpwalk/bulk on ciscoIfExtensionMib detects OID not increasing error & walk aborts.
|
|
Headline: N9k / Installing multiple SMUs do not remain committed after reload.
Step 1: Check if 1.0.0 is active switch# show install activeBoot Image: NXOS Image: bootflash:/nxos.7.0.3.I7.9.binActive Packages: nxos.CSCvx18710-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000 nxos.CSCvx18710_lc_x86-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000 Step 2: If 1.0.0 version is active, then deactivate it. This will require reload. switch# install deactivate nxos.CSCvx18710-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000 nxos.CSCvx18710_lc_x86-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000 ====================================================== !!!WARNING!!This is a reload patch and system will be reloaded if you proceed with patch operation. ======================================================= Do you want to continue (y/n)?: [n] y[####################] 100% Step 3: Check show install inactive and make sure 1.0.0 version have inactive status and then do install commit Switch# show install inactiveBoot Image: NXOS Image: bootflash:/nxos.7.0.3.I7.9.binInactive Packages: nxos.CSCvx18710-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000 nxos.CSCvx18710_lc_x86-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000switch# install commit[####################] 100% Step 4: Install remove 1.0.0 versionswitch# install remove nxos.CSCvx18710-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000Proceed with removing nxos.CSCvx18710-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000? (y/n)? [n] y[####################] 100%switch# install remove nxos.CSCvx18710_lc_x86-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000Proceed with removing nxos.CSCvx18710_lc_x86-n9k_ALL-1.0.0-7.0.3.I7.9.lib32_n9000? (y/n)? [n] y[####################] 100% Step 5: Download 1.0.1 version and install add,activate,commit. This doesn’t require reloadinfra-3164-2# install add nxos.CSCvx18710-n9k_ALL-1.0.1-7.0.3.I7.9.lib32_n9000.rpm activate Adding the patch (/nxos.CSCvx18710-n9k_ALL-1.0.1-7.0.3.I7.9.lib32_n9000.rpm)[####################] 100%Activating the patch (/nxos.CSCvx18710-n9k_ALL-1.0.1-7.0.3.I7.9.lib32_n9000.rpm)[####################] 100%switch# install commit[####################] 100% |
|
Headline: ECMP/port-channel hashing broken for non-GTP tunnelled unicast when gtpu load-sharing enabled
|
|
Headline: Port-security port with switchport mode private-vlan host goes Sec-violation errDisable when flapped.
|
|
Headline: n9k F&L: NVE Interface state: nve-intf-del-peer-cleanup-pending after interface NVE shut
|
|
Headline: dme - vpc dual-active exclude interface-vlan fails for non-default reserved vlan
*Use the default system reserved VLANs. OR *Upgrading from 9.3(4) with the config in place to an impacted version (9.3.5, 9.3.6 or 9.3.7) and the issue will not manifest unless changes are made to the dual-active exclude interface-vlan list or a "reload ascii" is performed. |
|
Headline: OSPF memory leak causes OSPF process to crash
--- ------ -------- --------------- -------- ------------------------- 1 1 1 ospf-3001 27491 2021-02-18 02:08:30
1. Avoid clearing routes if possible. 2. Manual restart of the process using:N9K# restart ospf <ospf-instance-name> |
|
Headline: MAC addresses aren't fully synced between VPC peers
|
|
Headline: dhclient crash when offer contains "log-server" option
|
|
Headline: Packets with a bad L4 checksum will be dropped in Nexus 9000-FX3
|
|
Headline: VXLAN-EVPN IR - vMCT PIP replication for BUM broken when empty Remote IR list
|
|
Headline: Not able to configure Tx (or both) SPAN direction for FEX port-channel source interface
N9K(config)# no monitor session 10 N9K(config)# monitor session 10 N9K(config)# source interface Ethernet113/1/3 both N9K(config)# <<<<< command is correctly accepted |
|
Headline: issues seen when gnmi/grpc connection with ipv6 default address connectivity
|
|
Headline: Memory leak on smnp due to STATSCLIENT_MEM_lib_portcl_request
''%SYSMGR-2-SERVICE_CRASHED: Service "snmpd" (PID 19371) hasn't caught signal 6 (core will be saved).''The respective core files are corrupted due to memory leaking. The memory leak can be verified by comparing the output of ''show system internal snmp mem-stats detail'' in between crashes.<div style="font-family:courier;white-space:pre;">Nexus# show system internal processes memory PID TTY STAT TIME MAJFLT TRS RSS VSZ %MEM COMMAND12240 ? Ssl 00:43:42 0 0 2833048 3511816 11.5 /isan/bin/snmpd -fNexus#show system internal snmp mem-stats detailsPrivate Mem stats for UUID : Stats Client Library(1047) Max types: 57-----------------------------------------------------------------------------TYPE NAME ALLOCS BYTES CURR MAX CURR MAX 32 STATSCLIENT_MEM_lib_portcl_request 217206 217206 2798482104 2798482104</div><div style="font-family:courier;white-space:pre;">Nexus#show system internal processes memory PID TTY STAT TIME MAJFLT TRS RSS VSZ %MEM COMMAND12240 ? Ssl 00:51:34 0 0 3331808 4010504 13.5 /isan/bin/snmpd -fNexus#show system internal snmp mem-stats detailsPrivate Mem stats for UUID : Stats Client Library(1047) Max types: 57-----------------------------------------------------------------------------TYPE NAME ALLOCS BYTES CURR MAX CURR MAX 32 STATSCLIENT_MEM_lib_portcl_request 256648 256648 3306652832 3306652832</div>
1. Disable the polling of information from Fex with interfaces in failure state. 2. Avoid FEX interfaces in failure state. |
|
Headline: All ports stop passing unicast traffic
|
|
Headline: N9K: nginx session flood if switch removed from DCNM with tracker enabled
|
|
Headline: Packet loss after reload of VXLAN BGP EVPN vPC VTEP with eBGP underlay
|
|
Headline: N9K-C9332C: Interfaces with 1Gbps transceivers do not go down when link signal is lost
|
|
Headline: IP-in-IP packets dropped on the peer-link
|
|
Headline: FIPs mode enabled+ nxapi disabled: switch reload allows access to nginx/nxapi sandbox port 80,443
1. Switch reports ports 80 and 443 are open despite feature nxapi disabledTDC1P1-Rack01-BMC-1# show sockets connection tcp | in '*(80)|*(443)' n 1[host]: tcp LISTEN 0 *(80) <<< port should be closed Wildcard 0 *(*)--[host]: tcp6 LISTEN 0 *(80) <<< port should be closed Wildcard 0 *(*)--[host]: tcp LISTEN 0 *(443) <<< port should be closed Wildcard 0 *(*)--[host]: tcp6 LISTEN 0 *(443) <<< port should be closed Wildcard 0 *(*) 2. user admin with valid password can open browser to NXAPI Sandbox despite feature disabled3. with feature bash enabled, find that nginx process was restarted, despite feature nxapi disabledTDC1P1-Rack01-BMC-1# run bash sudo pgrep -l nginx12616 nginx14059 nginx_1_fe14138 nginx_1_fe
See https://www.cisco.com/c/en/us/td/docs/dcn/nx-os/nexus9000/101x/programmability/cisco-nexus-9000-series-nx-os-programmability-guide-release-101x/m-n9k-nx-api-cli-101x.html, section - "Restricting Access to NX-API" for more details. For the purposes of this defect and workaround those limitations are not applicable. |
|
Headline: N9K-C93180YC-FX3 vPC fabric peering- Vxlan traffic fails to be bounced over fabric-ports
|
|
Headline: Aclqos crash on ravl_insert and ravl_free
|
|
Headline: N9k ITD-NAT and User defined PBR applied to same interface may cause inconsistencies in aclqos table
|
|
Headline: Packets forwarded with Incorrect MPLS labels when using N9k layer 2 evpn over segment routing
|
|
Headline: N9K/FX Series - Egress IFACL Label allocation Exhaustion/Failure is handled incorrectly
|
|
Headline: PBR not correctly programmed with scaled L2 egress port-channel
|
|
Headline: Traffic blackhole when both uplinks of compute to ToR are flapped
|
|
Headline: Mac address disabled on ports after removing VPC Peer-link from configuration
sh bfd neighbors detail: sh bfd neighbors details OurAddr NeighAddr LD/RD RH/RS Holdown(mult) State Int Vrf Type 10.3.200.254 10.3.200.253 1090519044/0 Down N/A(3) Down Vlan200 default SH Session state is Down and not using echo functionSession type: SinglehopLocal Diag: 0, Demand mode: 0, Poll bit: 0, Authentication: NoneMinTxInt: 0 us, MinRxInt: 0 us, Multiplier: 0Received MinRxInt: 0 us, Received Multiplier: 0Holdown (hits): 0 ms (0), Hello (hits): 0 ms (0)Rx Count: 0, Rx Interval (ms) min/max/avg: 0/0/0 last: 0 ms agoTx Count: 0, Tx Interval (ms) min/max/avg: 0/0/0 last: 0 ms agoRegistered protocols: ospfDowntime: 0 days 0 hrs 1 mins 28 secs, Downcount: 0Last packet: Version: 0 - Diagnostic: 0 State bit: AdminDown - Demand bit: 0 Poll bit: 0 - Final bit: 0 Multiplier: 0 - Length: 24 My Discr.: 0 - Your Discr.: 0 Min tx interval: 0 - Min rx interval: 0 Min Echo interval: 0 - Authentication bit: 0 Hosting LC: 0, Down reason: No Diagnostic, Reason not-hosted: if_index type invalid <<<<<<<<<<<<
|
|
Headline: QOSMGR_MEM_port_grp_mem_t memory leak in the ipqosmgr process
|
|
Headline: Multicast traffic is not forwarded out on ports 5 through 8 on N9K-X9408PC-CFP2.
|
|
Headline: Nexus 9000 - NTP access-group peer command not working after reload.
|
Bug ID |
Description |
On Cisco Nexus N2K-C2348TQ HIFs fail to utilize redundant Port-Channel links, to NIF, during link failover events. |
The following tables list the Cisco Nexus 9000 Series hardware that Cisco NX-OS Release 9.3(8) supports. For additional information about the supported hardware, see the Hardware Installation Guide for your Cisco Nexus 9000 Series device.
Table 1. Cisco Nexus 9500 Switches
Product ID |
Description |
N9K-C9504 |
7.1-RU modular switch with slots for up to 4 line cards in addition to two supervisors, 2 system controllers, 3 to 6 fabric modules, 3 fan trays, and up to 4 power supplies. |
N9K-C9508 |
13-RU modular switch with slots for up to 8 line cards in addition to two supervisors, 2 system controllers, 3 to 6 fabric modules, 3 fan trays, and up to 8 power supplies. |
N9K-C9516 |
21-RU modular switch with slots for up to 16 line cards in addition to two supervisors, 2 system controllers, 3 to 6 fabric modules, 3 fan trays, and up to 10 power supplies. |
Table 2. Cisco Nexus 9500 Cloud Scale Line Cards
Product ID |
Description |
Maximum Quantity |
||
Cisco Nexus |
Cisco Nexus |
Cisco Nexus |
||
N9K-X97160YC-EX |
Cisco Nexus 9500 48-port 10/25-Gigabit Ethernet SFP28 and 4-port 40/100 Gigabit Ethernet QSFP28 line card |
4 |
8 |
16 |
N9K-X9732C-EX |
Cisco Nexus 9500 32-port 40/100 Gigabit Ethernet QSFP28 line card |
4 |
8 |
16 |
N9K-X9732C-FX |
Cisco Nexus 9500 32-port 40/100 Gigabit Ethernet QSFP28 line card |
4 |
8 |
16 |
N9K-X9736C-EX |
Cisco Nexus 9500 36-port 40/100 Gigabit Ethernet QSFP28 line card |
4 |
8 |
16 |
N9K-X9736C-FX |
Cisco Nexus 9500 36-port 40/100 Gigabit Ethernet QSFP28 line card |
4 |
8 |
16 |
N9K-X9788TC-FX |
Cisco Nexus 9500 48-port 1/10-G BASE-T Ethernet and 4-port 40/100 Gigabit Ethernet QSFP28 line card |
4 |
8 |
16 |
Table 3. Cisco Nexus 9500 R-Series Line Cards
Product ID |
Description |
Maximum Quantity |
|
Cisco Nexus 9504 |
Cisco Nexus9508 |
||
N9K-X9636C-R |
Cisco Nexus 9500 36-port 40/100 Gigabit Ethernet QSFP28 line card |
4 |
8 |
N9K-X9636C-RX |
Cisco Nexus 9500 36-port 40/100 Gigabit Ethernet QSFP28 line card |
4 |
8 |
N9K-X9636Q-R |
Cisco Nexus 9500 36-port 40 Gigabit Ethernet QSFP line card |
4 |
8 |
N9K-X96136YC-R |
Cisco Nexus 9500 16-port 1/10 Gigabit, 32-port 10/25 Gigabit, and 4-port 40/100 Gigabit Ethernet line card |
4 |
8 |
Table 4. Cisco Nexus 9500 Classic Line Cards
Product ID |
Description |
Maximum Quantity |
||
Cisco Nexus |
Cisco Nexus |
Cisco Nexus |
||
N9K-X9408C-CFP2 |
Line card with 8 100 Gigabit CFP2 ports |
4 |
8 |
16 |
N9K-X9432C-S |
Cisco Nexus 9500 32-port 40/100 Gigabit Ethernet QSFP28 line card |
4 |
8 |
N/A |
N9K-X9432PQ |
Cisco Nexus 9500 32-port 40 Gigabit Ethernet QSFP+ line card |
4 |
8 |
16 |
N9K-X9636PQ |
Cisco Nexus 9500 36-port 40 Gigabit Ethernet QSFP+ line card |
4 |
8 |
N/A |
N9K-X9464PX |
Cisco Nexus 9500 48 1/10-Gigabit SFP+ and 4-port 40-Gigabit Ethernet QSFP+ line card |
4 |
8 |
16 |
N9K-X9464TX |
Cisco Nexus 9500 48 port 1/10-Gigabit BASE-T Ethernet and 4-port 40-Gigabit Ethernet QSFP+ line card |
4 |
8 |
16 |
N9K-X9464TX2 |
Cisco Nexus 9500 48 port 1/10-Gigabit BASE-T Ethernet and 4-port 40-Gigabit Ethernet QSFP+ line card |
4 |
8 |
16 |
N9K-X9536PQ |
Cisco Nexus 9500 36-port 40 Gigabit Ethernet QSFP+ line card |
4 |
8 |
16 |
N9K-X9564PX |
Cisco Nexus 9500 48 1/10-Gigabit SFP+ and 4 port 40-Gigabit Ethernet QSFP+ line card |
4 |
8 |
16 |
N9K-X9564TX |
Cisco Nexus 9500 48 port 1/10-Gigabit BASE-T Ethernet and 4 port 40-Gigabit Ethernet QSFP+ line card |
4 |
8 |
16 |
Table 5. Cisco Nexus 9500 Cloud Scale Fabric Modules
Product ID |
Description |
Minimum |
Maximum |
Table 6. Cisco Nexus 9500 R-Series Fabric Modules
Product ID |
Description |
Minimum |
Maximum |
Table 7. Cisco Nexus 9500 Fabric Modules
Product ID |
Description |
Minimum |
Maximum |
N9K-C9504-FM |
Cisco Nexus 9504 40-Gigabit fabric module |
3 |
6 |
N9K-C9508-FM |
Cisco Nexus 9508 40-Gigabit fabric module |
3 |
6 |
N9K-C9516-FM |
Cisco Nexus 9516 40-Gigabit fabric module |
3 |
6 |
N9K-C9504-FM-S |
Cisco Nexus 9504 100-Gigabit fabric module |
4 |
4 |
N9K-C9508-FM-S |
Cisco Nexus 9508 100-Gigabit fabric module |
4 |
4 |
Table 8. Cisco Nexus 9500 Fabric Module Blanks with Power Connector
Product ID |
Description |
Minimum |
Maximum |
Cisco Nexus 9508 Fabric blank with Fan Tray Power Connector module |
|||
Cisco Nexus 9516 Fabric blank with Fan Tray Power Connector module |
Table 9. Cisco Nexus 9500 Supervisor Modules
Supervisor |
Description |
Quantity |
N9K-SUP-A |
1.8-GHz supervisor module with 4 cores, 4 threads, and 16 GB of memory |
2 |
N9K-SUP-A+ |
1.8-GHz supervisor module with 4 cores, 8 threads, and 16 GB of memory |
2 |
N9K-SUP-B |
2.2-GHz supervisor module with 6 cores, 12 threads, and 24 GB of memory |
2 |
N9K-SUP-B+ |
1.9-GHz supervisor module with 6 cores, 12 threads, and 32 GB of memory |
2 |
NOTE: N9K-SUP-A and N9K-SUP-A+ are not supported on Cisco Nexus 9504 and 9508 switches with -R line cards.
Table 10. Cisco Nexus 9500 System Controller
Product ID |
Description |
Quantity |
N9K-SC-A |
Cisco Nexus 9500 Platform System Controller Module |
2 |
Table 11. Cisco Nexus 9500 Fans and Fan Trays
Product ID |
Description |
Quantity |
Table 12. Cisco Nexus 9500 Power Supplies
Product ID |
Description |
Quantity |
Cisco Nexus Switches |
Table 13. Cisco Nexus 9200 and 9300 Fans and Fan Trays
Product ID |
Description |
Quantity |
Cisco Nexus Switches |
Fan 1 module with port-side intake airflow (burgundy coloring) |
|||
Fan 2 module with port-side intake airflow (burgundy coloring) |
|||
Fan 3 module with port-side intake airflow (burgundy coloring) |
|||
|
Fan module with port-side exhaust airflow (blue coloring)
|
||
Fan module with port-side intake airflow (burgundy coloring) |
|||
|
Fan module with port-side exhaust airflow (blue coloring)
|
||
Fan module with port-side intake airflow (burgundy coloring) |
|||
Fan module with port-side intake airflow (burgundy coloring) |
92160YC-X |
||
92160YC-X |
|||
93108TC-FX3P 93180YC-FX3Sb |
|||
Fan module with port-side intake airflow (burgundy coloring) |
93108TC-FX3P 93180YC-FX3Sb |
||
Fan module with port-side exhaust airflow (burgundy coloring) |
aFor specific fan speeds see the Overview section of the Hardware Installation Guide.
b This switch runs with +1 redundancy mode so that if one fan fails, the switch can sustain operation. But if a second fan fails, this switch is not designed to sustain operation. Hence before waiting for the major threshold temperature to be hit, the switch will power down due to entering the fan policy trigger command.
Table 14. Cisco Nexus 9200 and 9300 Power Supplies
Product ID |
Description |
Quantity |
Cisco Nexus Switches |
NXA-PAC-500W-PE |
500-W AC power supply with port-side exhaust airflow (blue coloring) |
2 |
93108TC-EX |
NXA-PAC-500W-PI |
500-W AC power supply with port-side intake airflow (burgundy coloring) |
2 |
93108TC-EX |
N9K-PAC-650W |
650-W AC power supply with port-side intake (burgundy coloring) |
2 |
9332PQ |
N9K-PAC-650W-B |
650-W AC power supply with port-side exhaust (blue coloring) |
2 |
9332PQ |
NXA-PAC-650W-PE |
650-W power supply with port-side exhaust (blue coloring) |
2 |
92160YC-X |
NXA-PAC-650W-PI |
650-W power supply with port-side intake (burgundy coloring) |
2 |
92160YC-X |
NXA-PAC-750W-PE |
750-W AC power supply with port-side exhaust airflow (blue coloring) 1 |
2 |
9336C-FX2 |
NXA-PAC-750W-PI |
750-W AC power supply with port-side exhaust airflow (burgundy coloring) 1 |
2 |
9336C-FX2 |
NXA-PAC-1100W-PE2 |
1100-W AC power supply with port-side exhaust airflow (blue coloring) |
2 |
93240YC-FX2 |
NXA-PAC-1100W-PI2 |
1100-W AC power supply with port-side intake airflow (burgundy coloring) |
2 |
93240YC-FX2 |
NXA-PAC-1100W-PI |
Cisco Nexus 9000 PoE 1100W AC PS, port-side intake |
2 |
93108TC-FX3P |
NXA-PAC-1100W-PE |
Cisco Nexus 9000 PoE 1100W AC PS, port-side exhaust |
2 |
93108TC-FX3P |
NXA-PAC-1900W-PI |
Cisco Nexus 9000 PoE 1900W AC PS, port-side intake |
2 |
93108TC-FX3P |
N9K-PAC-1200W |
1200-W AC power supply with port-side intake airflow (burgundy coloring) |
2 |
93120TX |
N9K-PAC-1200W-B |
1200-W AC power supply with port-side exhaust airflow (blue coloring) |
2 |
93120TX |
NXA-PAC-1200W-PE |
1200-W AC power supply with port-side exhaust airflow (blue coloring) |
2 |
9272Q |
NXA-PAC-1200W-PI |
1200-W AC power supply with port-side intake airflow (burgundy coloring) |
2 |
9272Q |
N9K-PUV-1200W |
1200-W Universal AC/DC power supply with bidirectional airflow (white coloring) |
2 |
92160YC-X |
NXA-PDC-930W-PE |
930-W DC power supply with port-side exhaust airflow (blue coloring) |
2 |
9272Q |
NXA-PDC-930W-PI |
930-W DC power supply with port-side intake airflow (burgundy coloring) |
2 |
9272Q |
NXA-PDC-1100W-PE |
1100-W DC power supply with port-side exhaust airflow (blue coloring) |
2 |
93240YC-FX2 |
NXA-PDC-1100W-PI |
1100-W DC power supply with port-side intake airflow (burgundy coloring) |
2 |
93240YC-FX2 |
UCSC-PSU-930WDC |
930-W DC power supply with port-side intake (green coloring) |
2 |
92160YC-X |
UCS-PSU-6332-DC |
930-W DC power supply with port-side exhaust (gray coloring) |
2 |
92160YC-X |
NXA-PHV-1100W-PE |
1100-W AC power supply with port-side exhaust airflow (blue coloring) |
2 |
93240YC-FX2 |
NXA-PHV-1100W-PI |
1100-W AC power supply with port-side intake airflow (burgundy coloring) |
2 |
93240YC-FX2 |
NXA-PAC-2KW-PE |
2000-W AC power supply with port-side exhaust airflow (blue coloring) |
2 |
9364C-GX |
NXA-PAC-2KW-PI |
2000-W AC power supply with port-side intake airflow (burgundy coloring) |
2 |
9364C-GX |
NXA-PDC-2KW-PE |
2000-W DC power supply with port-side exhaust airflow (blue coloring |
2 |
9364C-GX |
NXA-PDC-2KW-PI |
2000-W DC power supply with port-side intake airflow (burgundy coloring) |
2 |
9364C-GX |
N2200-PAC-400W |
400-W AC power supply with port-side exhaust airflow (blue coloring) |
2 |
92348GC-X |
N2200-PAC-400W-B |
400-W AC power supply with port-side intake airflow (burgundy coloring) |
2 |
92348GC-X |
N2200-PDC-350W-B |
350-W DC power supply with port-side intake airflow |
2 |
92348GC-X |
N2200-PDC-400W |
400-W DC power supply with port-side exhaust airflow (blue coloring) |
2 |
92348GC-X |
Table 15. Cisco Nexus 9200 and 9300 Switches
Table 16. Cisco Nexus 9000 Series Uplink Modules
Cisco Nexus Switch |
Description |
An enhanced version of the Cisco Nexus N9K-M6PQ uplink module. |
|
Cisco Nexus 9300 uplink module with 12 40-Gigabit Ethernet QSPF+ ports. |
To determine which transceivers and cables are supported by a switch, see the Transceiver Module (TMG) Compatibility Matrix. To see the transceiver specifications and installation information, see the Install and Upgrade Guides.
Cisco Network Insights for Data Center
Cisco NX-OS Release 9.3(8) supports the Cisco Network Insights Advisor (NIA) and Cisco Network Insights for Resources (NIR) on Cisco Nexus 9200, 9300-EX, and 9300-FX platform switches and 9500 platform switches with -EX/FX line cards. For more information, see the Cisco Network Insights documentation.
To perform a software upgrade or downgrade, follow the instructions in the Cisco Nexus 9000 Series NX-OS Software Upgrade and Downgrade Guide, Release 9.3(x). For information about an In Service Software Upgrade (ISSU), see the Cisco NX-OS ISSU Support Matrix.
Exceptions
Cisco Nexus 9200, 9300-EX, and 9300-FX Platform Switches
● ACL filters to span subinterface traffic on the parent interface
● FEX (not supported for Cisco Nexus 9200 platform switches)
● GRE v4 payload over v6 tunnels
● IP-in-IP (not supported on the Cisco Nexus 92160 switch)
● Maximum Transmission Unit (MTU) checks for packets received with an MPLS header
● NetFlow (not supported on Cisco Nexus 9200 platform switches)
● Packet-based statistics for Traffic Storm Control (only byte-based statistics are supported)
● PVLANs (not supported on Cisco Nexus 9200 platform switches)
● PXE boot of the Cisco NX-OS image from the loader (not supported for Cisco Nexus 9272PQ and 92160YC switches)
● Q-in-VNI (not supported on Cisco Nexus 9200 platform switches)
● Q-in-Q for VXLAN (not supported on Cisco Nexus 9200 and 9300-EX platform switches)
● Q-in-VNI (not supported on Cisco Nexus 9200 platform switches)
● Resilient hashing for port channels
● SVI uplinks with Q-in-VNI (not supported for Cisco Nexus 9300-EX platform switches)
● Traffic Storm Control for copy-to-CPU packets
● Traffic Storm Control with unknown multicast traffic
● Tx SPAN for multicast, unknown multicast, and broadcast traffic
● VACL redirects for TAP aggregation
Cisco Nexus 9300-FX3 Platform Switches
The following features are not supported for the Cisco Nexus 9300-FX3 Platform switches:
● ACL with DSCP Wildcard Mask
● ARP Suppression with Reflective Relay
● Dynamic ACL - Named ACL support for applying blacklist/limited VLAN access for devices
● ECMP Hashing based on GRE Inner IP Header
● Enhanced ISSU
● Enhanced Policy-Based Routing (ePBR)
● ePBR Multi-Hop
● ePBR with Probes
● ePBR with User-Defined Probes
● IPv6 MIB support (IP-MIB)
● Multicast Service Reflection (Ingress, PIM-border, Egress)
● Multiple LLDP neighbors per physical interface
● Secure VXLAN EVPN Multi-Site using CloudSec
● Selective Q-in-VNI + Advertise PIP on a VTEP
● Selective Q-in-VNI + VXLAN VLAN on the same port
● Standard ISSU
● Symmetric Hashing - ECMP (Inner DA)
● Unidirectional Ethernet (UDE)
● VXLAN EVPN with downstream VNI
● VXLAN over parent interface that also carries sub-interfaces
Cisco Nexus 9300-GX Platform Switches
The following features are not supported for the Cisco Nexus 9300-GX platform switches:
● Autonegotiation on all ports
● FC-FEC for Cisco Nexus 9316D-GX and 93600CD-GX switches is not supported on the second lane of the 50x2 breakout port.
● FEX
● Multicast over GRE
Cisco Nexus N9K-X9408PC-CFP2 Line Card and 9300 Platform Switches
● FEX (supported on some Cisco Nexus 9300 platform switches)
● Flows other than 40G
● Multichassis EtherChannel Trunk (MCT)
● Precision Time Protocol (PTP)
● PVLAN (supported on Cisco Nexus 9300 platform switches)
● Shaping support on 100g port is limited
● SPAN destination/ERSPAN destination IP
FEX Modules
The following features are not supported for FEX modules:
● Active-Active FEX and straight-through FEX are not supported on the Cisco Nexus 92348GC switch.
● For Cisco Nexus 9500 platform switches, 4x10-Gb breakout for FEX connectivity is not supported.
Cisco Nexus N9K-X96136YC-R Line Card
Cisco Nexus N9K-X9736C-FX Line Card
● Ports 29-36 do not support 1 Gbps speed.
Cisco Nexus 9500 Cloud Scale (EX/FX) Line Cards
The following features are not supported for Cisco Nexus 9500 platform switches with -EX/FX line cards:
● IPv6 support for policy-based routing
● SPAN port-channel destinations
Cisco Nexus 9000 Series documentation: Cisco Nexus 9000 Series Switches
Cisco Nexus 9000 and 3000 Series NX-OS Switch License Navigator: Cisco Nexus 9000 and 3000 Series NX-OS Switch License Navigator
Cisco Nexus 9000 Series Software Upgrade and Downgrade Guide: Cisco Nexus 9000 Series NX-OS Software Upgrade and Downgrade Guide, Release 9.3(x)
Cisco Nexus 9000 Series FPGA/EPLD Upgrade Release Notes: Cisco Nexus 9000 Series FPGA/EPLD Upgrade Release Notes, Release 9.3(8)
Cisco Nexus 3000 and 9000 Series NX-API REST SDK User Guide and API Reference: Cisco Nexus NX-API Reference
Cisco NX-OS Supported MIBs: ftp://ftp.cisco.com/pub/mibs/supportlists/nexus9000/Nexus9000MIBSupportList.html
Supported FEX modules: Cisco Nexus 9000 Series Switch FEX Support Matrix
Licensing Information: Cisco NX-OS Licensing Guide
To provide technical feedback on this document, or to report an error or omission, please send your comments to nexus9k-docfeedback@cisco.com. We appreciate your feedback.
Legal Information
Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. To view a list of Cisco trademarks, go to this URL: www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word partner does not imply a partnership relationship between Cisco and any other company. (1721R)
Any Internet Protocol (IP) addresses and phone numbers used in this document are not intended to be actual addresses and phone numbers. Any examples, command display output, network topology diagrams, and other figures included in the document are shown for illustrative purposes only. Any use of actual IP addresses or phone numbers in illustrative content is unintentional and coincidental.
© 2021 Cisco Systems, Inc. All rights reserved.